Service Reference Variant

6.15.1 · Update Security Credentials (KRP)

Service details

Identifiers, rules, and applicability

Service reference
6.15
Service Reference Variant
6.15.1
DUIS section
3.8.67
Command variants
4, 5, 6, 7
DUIS possible responses
AcknowledgementResponse to Transform Request - PreCommand FormatService Response from Device - GBCSPayloadResponse to a Command for Local Delivery Request - LocalCommand FormatFutureDatedDeviceAlertMessageCountersigned SMETS1 Response
Critical
Yes
Sensitive response
No
Protection against replay
Yes
On demand
Yes
Future dated
Device
DSP scheduled
No
DCC only
No
SMETS1 applicability
Yes
SAPC requirement
Mandatory
DUIS applicability
3.0, 3.1, 4.0, 5.0, 5.1, 5.2, 5.3

Specific Errors

Response codes and descriptions

Response CodeResponse Code Description
E061501
The combination of User Role,Remote Party Role and Device Type is incorrect
E061504
The Remote Party New Prepayment Top Up Floor Seq Number data item is not applicable to the Request
E061505
The Certificate Type is not applicable to the Device Type
E061506
Future Dating / Remote Party Role mismatch - The RemotePartyRole is not Supplier or LoadController
E061507
The Certificate Type is not applicable to the Remote Party Role
E061509
The Device Type is ESME and ‘LoadController’ is specified as the RemotePartyRole in the Service Request, however the firmware version recorded in the SMI for the Device is not at GBCS version 4.0 or later

Source: DUIS 3.8.67.3

SMETS1-specific validation

Additional SMETS1 conditions are shown separately from the SRV-specific DUIS table.

SMETS1 supplementary validation
E061508

Check that the role of the User submitting the Service Request and RemotePartyRole align. Specifically if the User’s role is ES or GS, the RemotePartyRole must be Supplier. If the User’s role is GT or ED, the RemotePartyRole must be NetworkOperator.

Applies to: SMETS1 Devices only

Source: DUIS 1.4.6 Table 2

GBCS Use Case

Use cases, device coverage, and applicability

Use Case / Message Code
CS02b0x0102
DUIS Applicability
v3.0 – v5.3
GBCS Applicability
v1.0 – v4.3
GBCS Criticality
Critical
Sensitive Response
No
Future Dated
Device
CommandESMENot always GBT
CommandGSMENot always GBT
CommandGPFNot always GBT
CommandHCALCSAlways GBT
SMETS1 Applicable
NoYes
Eligible Roles
EISESMEHCALCS
GISGSMEGPF
SMETS1 note

HCALCS is not a valid SMETS1 Device Type

Use Case / Message Code
CS02b0x0103
DUIS Applicability
v3.0 – v5.3
GBCS Applicability
v1.0 – v4.3
GBCS Criticality
Critical
Sensitive Response
No
Future Dated
No
CommandESMENot always GBT
CommandGPFNot always GBT
SMETS1 Applicable
Yes
Eligible Roles
EISENOESME
GISGNOGPF
Use Case / Message Code
CS02g0x0126
DUIS Applicability
v4.0 – v5.3
GBCS Applicability
v4.0 – v4.3
GBCS Criticality
Critical
Sensitive Response
No
Future Dated
No
GBT
No
SMETS1 Applicable
No
Eligible Roles
EISESME

DUIS Service Definition

Data items and DCC processing

Request data items

Table 184: UpdateSecurityCredentialsKRP (sr:UpdateSecurityCredentialsKRP) data items
Data ItemDescription / Valid SetTypeMandatoryDefaultUnits
ExecutionDateTimeA User shall only add this Data Item to the Service Request where they require the Service Request to be executed at a future date and time. The UTC date and time the User requires the Command to be executed on the Device Date-time in the future that is either <= current date + 30 days or the date = ‘3000-12-31T00:00:00Z’xs:dateTimeNoNoneUTC Date-Time
RemotePartyRoleRemote Party Role for which the Certificates are being updated Valid Set in this context from the enumeration is; Supplier NetworkOperator LoadControllersr:RemotePartyRole Restriction base xs:token (Enumeration)YesNoneN/A
RemotePartyFloorSeqNumberNot relevant if the RemotePartyRole is NetworkOperator. Otherwise this value will be used to prevent replay of Update Security Credentials Commands, and other Commands, for the affected Remote Party.sr:floorSequenceNumber (Restriction of xs:nonNegativeInteger minInclusive = 0, maxInclusive = 9223372036854775807)No unless the value of RemotePartyRole is LoadController, in which case RemotePartyFloorSeqNumber must be present.NoneN/A
RemotePartyPrepaymentTopUpFloorSeqNumberOnly applicable when the Command changes Supplier Certificates and Counters on a Meter and the Counter for its Prepayment Top Ups is different to that used for other Commands. This value will be used to prevent replay of Prepayment Top Up Commandssr:floorSequenceNumber (Restriction of xs:nonNegativeInteger minInclusive = 0, maxInclusive = 9223372036854775807Remote Party Role = Supplierand Device Type = ESME or GSME: No Otherwise: N/ANoneN/A
ReplacementCertificatesThis structure provides a list of the replacements. Each replacement contains a replacement Certificate, its Key Usage and Cell Usage.sr:ReplacementCertificatesKRPYesNoneN/A
CertificationPathCertificatesThis structure provides the Certificates needed to Confirm Validity of the new end entity Certificate against the Root OCA Certificate held on the Device. The number of these may be fewer than the number of replacement Certificates (e.g. a Supplier may replace all of its Certificates but may only need to supply one Issuing OCA Certificate to link them all back to root.sr:Certificate (xs:base64Binary minOccurs = “1”, maxOccurs = “3”)YesNoneN/A
ApplyTimeBasedCPVChecksSpecify whether the time based Confirm Validity checkshould be appliedxs:BooleanYesNoneN/A
Table 185: ReplacementCertificates (sr:ReplacementCertificatesKRP) data items
Data ItemDescription / Valid SetTypeMandatoryDefaultUnits
SupplierOrNetworkOperatorCertificatesCertificates to be included in Requests to update Supplier or Network Operator or Load Controller Credentials.sr:SupplierOrNetworkOperatorCertificatesKRPYesNoneN/A
Table 186: SupplierOrNetworkOperatorCertificates (sr:SupplierOrNetworkOperatorCertificatesKRP) data items
Data ItemDescription / Valid SetTypeMandatoryDefaultUnits
DigitalSigningCertificateThe new Digital Signing Certificate to be placed in the Remote Party Role Key Usage digitalSignature (Cell Usage Management) on the Device.sr:Certificate (xs:base64Binary)NoNoneN/A
KeyAgreementCertificateThe new Key Agreement Certificate to be placed in the Remote Party Role Key Usage keyAgreement (Cell Usage Management) on the Devicesr:Certificate (xs:base64Binary)HCALCS: N/A Otherwise: NoNoneN/A
KeyAgreementTopUpCretificateThe new Key Agreement Certificate to be placed in te Supplier Remote Party Role Key Usage keyAgreement (Cell Usage prePaymentTopUp) on the Device for those Suppliers that use different Originator Counters for Prepayment Top Up.sr:Certificate (xs:base64Binary)Remote Party Role = Supplier, and Device Type = ESME or GSME: No Otherwise: N/ANoneN/A

Additional System Processing - DUIS

When the DCC receives a Response indicating Success from an Update Security Credentials command for all certificates and where the Remote Party whose certificate has been placed on the Device is not the sender of the Service Request, the DCC shall send a DCC Alert N42 to each of the relevant User(s) whose certificate has been placed on the Device.

Where the SMI Status of the associated Device is ‘Recovered’ and when all the Security Credentails from Access Control Broker Organisation Certificates that have been placed in the Supplier and Network Operator Trust Anchor Cells as part of the recovery process have been replaced with those from Organisation Certificates of the relevant Supplier and/or Network Operator, the DCC shall update the Device Status to the SMI Status it held immediately prior to the recovery process (SMI Status prior to the ‘Recovery’ SMI Status).

For each certificate specified in a Response or Alert from the Device as being successfully updated by the Update Security Credentials command, the DCC Systems shall update the Smart Metering Inventory with the new certificate identifier as a record of the certificate held in the relevant Trust Anchor Cell on that Device.

Message Patterns & Examples

Pattern explorer

Open Message Patterns →

SMETS1 Supporting Requirements

Device-model variations and equivalent steps

Review the Section 18 requirements and their applicability across the documented manufacturer, Device Type, model, and firmware profiles.

Open S1SR Requirements →